← Back to Kira Sun
Enterprise UX · Risk Management

Luminescent Tower

Designing the first risk management tool at Amazon — turning a scattered, spreadsheet-driven process into a single system teams actually trust.

Final product — dashboard overview and risk detail flow.
My Role
Lead Product DesignerEnd-to-end: research, IA, interaction, visual, design system
Timeline & Team
8 months · 20241 designer, 1 PM, 6 engineers, 1 researcher
Tools & Platform
Figma · FigJamResponsive web · internal enterprise tool
1st
First dedicated risk management tool built at Amazon
-60%
Reduction in time to log and route a new risk
12
Teams onboarded within the first quarter of launch
01 — The Challenge

Risk lived in a hundred spreadsheets

Before this project, risk tracking happened wherever each team could manage it — spreadsheets, wiki pages, email threads. There was no shared definition of what a "risk" was, no consistent severity scale, and no way for leadership to see aggregate exposure across orgs.

That created three compounding problems: risks were logged inconsistently, ownership was ambiguous, and the same issue got reported multiple times by different teams. Leadership was making decisions on an incomplete picture.

Design question

How do we create one system that is structured enough to aggregate risk data reliably, but flexible enough that a dozen very different teams will actually adopt it?

02 — Process

How I approached it

01
Discover
Stakeholder interviews, audit of existing spreadsheets and workflows
02
Define
Journey mapping, a shared risk taxonomy, prioritized requirements
03
Design
IA exploration, wireframes, interactive prototypes, usability testing
04
Deliver
Design system components, engineering handoff, post-launch iteration
03 — Research & Discovery

Talking to the people who log risk

I interviewed 14 people across three roles — risk owners who log issues, managers who triage them, and leaders who report upward. I also audited 20+ existing spreadsheets to understand what people were actually tracking versus what the official process asked for.

Add image → assets/p1-research-1.png
(affinity map / interview synthesis)
Affinity mapping 14 interviews into five recurring pain themes.
Add image → assets/p1-research-2.png
(spreadsheet audit)
Audit of existing spreadsheets revealed 9 different severity scales in use.

What I learned

"I know the risk. I just don't know where it's supposed to go."
04 — Key Insight

Structure has to be earned, not enforced

The instinct was to mandate a rigid taxonomy. But research showed that every previous attempt at enforcement had failed — people simply worked around it. The insight that reframed the project: if logging a risk is faster than not logging it, structure becomes a byproduct rather than a burden.

So instead of a long compliance form, I designed a progressive flow — capture the minimum viable risk in under a minute, then enrich it later as triage progresses. Structure emerges through the workflow rather than being demanded upfront.

05 — Exploration

From sketches to structure

I explored three information architectures: a linear queue, a severity-first matrix, and an ownership-based dashboard. Testing showed the dashboard model matched how managers actually think — they scan by ownership first, then drill into severity.

Add image → assets/p1-explore-1.png
Option A — linear queue
Add image → assets/p1-explore-2.png
Option B — severity matrix
Add image → assets/p1-explore-3.png
Option C — ownership dashboard (selected)

Testing what we chose

I ran moderated usability sessions with 8 participants on an interactive prototype. Two changes came directly out of those sessions: severity became a guided set of questions rather than a free choice, and duplicate detection surfaced inline while typing instead of after submission.

06 — The Solution

One system, three views

Quick capture

A single-screen entry flow that asks only what's needed to route a risk. Inline duplicate detection catches overlaps as the user types, cutting redundant entries significantly.

Add image → assets/p1-solution-capture.png
Quick capture — under a minute from intent to logged risk.

Guided severity

Rather than asking users to pick a number, the system asks about impact and likelihood in plain language and derives severity consistently. This made ratings comparable across teams for the first time.

Add image → assets/p1-solution-severity.png
Guided severity scoring replaces subjective self-rating.

Ownership dashboard

Managers see their team's exposure grouped by owner with trend indicators over time. Leadership gets the same data rolled up, so conversations start from a shared source of truth.

Add image → assets/p1-solution-dashboard.png
Ownership dashboard with trend over time, not just a snapshot list.
07 — Impact

What changed

Note: metrics shown are directional and rounded. Detailed figures are confidential.

08 — Reflection

What I'd do differently

I under-invested in the triage experience early on. I focused on capture because that was the loudest complaint, but managers turned out to be the group whose time was most wasted. If I ran this again, I'd map the full lifecycle before choosing where to start.

The lesson that stuck: adoption is a design problem, not a rollout problem. Every place we replaced a mandate with a genuinely faster path, usage followed on its own.

Next project
Neon Market
View next →